SAP security note 2378485, “Cross-Site Scripting (XSS) Vulnerability in Integrated Marketing Calendar”. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
The Integrated Marketing Calendar (IMC) contains a Cross-Site Scripting (XSS) vulnerability due to insufficient encoding of user-controlled inputs. Additionally, unnecessary and vulnerable SWF files are present in the BSP Application MKTCALENDAR_NEW.
Impacts:
- Defacement or Modification: Attackers can non-permanently deface or modify the displayed content on the website.
- Information Theft: Potential theft of user authentication information, including session data.
- User Impersonation: Ability to impersonate users and access information with the same rights as the target user.
Solution
Implement the appropriate correction instructions or install the relevant Support Packages to address the vulnerability.
References
Referenced by
Affected components
- BBPCRM (CRM > Marketing > Marketing Planner > Marketing Calendar): Versions 701, 702, 712, 713, 714
Full note on SAP: SAP Support Launchpad note 2378485
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



